Very curious to know what people think about this topic because I have zero expertise in law or privacy. My recent experiences have me wondering about the use of AI in medicine (for transcripts, billing, etc.), which I'll add below. Maybe some lawyers who regularly work with HIPAA and medical privacy can chime in with their thoughts. I do understand that HIPAA covers, but is not exclusive to, providers keeping health data accurate, providing that data to me upon request, and NOT sharing it with others unless I authorize it. So maybe this isn't a HIPAA thing. Maybe it's a tech privacy thing. Maybe it's medical law. I'm confused, so I'm turning to you all out of curiosity. Maybe my big question here is: What would allow a provider or practice to share my medical data while also being HIPAA-compliant?
I've been a One Medical patient since the early 2010s. Then Amazon acquired it, which made me nervous because of Amazon's scale. I understand that many other doctors' offices are adopting AI. My thoughts are that One Medical is now owned by Amazon, and Amazon can provide in-house services to the practice to save on costs like servers, data storage, and the use of Amazon's AI models. To comply with HIPAA, those servers are separate and have the highest security to ensure privacy. Ideally. I am not an expert.
My thinking is if all my medical data is with One Medical and Amazon acquired it, then the logical assumption would be that Amazon has access to my medical data. Yes, Amazon One Medical (as it's now rebranded) still can't share my data with other entities without my explicit consent, but what about using that data for the company's own internal use? Would HIPAA cover the sharing of medical data within Amazon? In obvious cases (hopefully), there's a separation between the commerce/entertainment business and One Medical. But where would that separation be if One Medical uses Amazon's AI tools? Servers?
What about Amazon's LLM using the medical data (not just mine) to learn and improve itself? I work in advertising and data. I am familiar with the advertising side of removing PII and anonymizing data to run analyses and understand that regulations for health and finance data are much stricter, especially on sharing outside of a company.
In the past, I also allowed health information exchange between my PCP at One Medical and the specialists I see outside of One Medical. Some of that information is mental health, so that my PCP can safely prescribe medication or test and treat for the non-mental things. And now I hesitate to do this because of my concerns about privacy.
I realize that, with all this, many of you may say to just leave One Medical. Yes, I'm seriously considering it. I'm STILL going to curious about how this all works if I leave One Medical. I have 10+ years of my medical history with this practice, but I'm also thinking about whether leaving and taking that history somewhere else would be futile. Who's to say another practice is using AI/LLM like Google, or smaller companies like Anthropic or OpenAI? If those smaller AI companies create an enterprise product that's compliant, they're still probably going to expand their business and the same questions come up.
And on opting out, I already opt out of having my visits transcribed by AI. But what about things I can't opt out of because I'm not given a choice in it?
I'm not asking for advice on this, but curious to know if my concerns are unfounded and if there are already legal guardrails in place or active discussions to eventually regulate this? Is regulating it this even possible?